Privacy & Security Policy

This website is operated by PA Pool Ltd (PA Pool), company number 05976612. At PA Pool we are committed to protecting the privacy of visitors to and users of our website at www.papool.co.uk (our Website). We strive to provide a safe, secure user experience.

The aim of this Privacy Policy is to inform you how we will collect and use any personal information which you provide through our Website, what we do with it and what controls you have over your personal information.

If we decide to change the substance of our Privacy Policy for PA Pool, we will post those changes through a prominent notice on the web site so that you will always know what information we gather, how we might use that information, and to whom we will disclose it. If at any time, you have questions or concerns about PA Pool's Privacy Policy, please feel free to email us at admin@papool.co.uk.

Your Privacy

PA Pool provides a forum where people looking to employ a personal assistant/carers (PA Users) and personal assistant/carers looking to find private employment (PAs) can manage their own recruitment/employment needs interactively themselves. The Service which PA Pool provides is not an employment agency or employment business.

At PA Pool we take our duty to process your personal information very seriously. This policy explains how we collect, manage, use and protect your personal information.

We may change this document from time to time to reflect the latest view of what we do with your information. Please check back frequently; you will be able to see if changes have been made by the date it was last updated.

Please refer to the sections below for more details on how and why we use your personal information:

1. Who are we?

2. What personal information we collect and how we use it

3. Legitimate interests

4. Sharing your information

5. Retaining your information

6. Your details on the web

7. What are your rights?

8. How to contact us

1. Who are we?

In this policy references to PA Pool, we or us are to PA Pool Limited, which is a company registered in England and Wales with company number 05976612, whose registered office is at 3 Pilkington Manor, High Street, Berkhamsted, Herts, HP4 2B.

The sole owner of PA Pool is Katy Etherington.

2. What personal information we collect and how we use it

What we collect

PA Pool is what’s known as the ‘controller’ of the personal information you provide to us.

When you register to use our Website as a PA or PA User we will always collect basic personal information about you like your name, postcode address, email address, date of birth and, if you are subscribing to use any of the paid features which form part of the Service, your payment details.

When you complete your profile as a member you have the option to provide other information about yourself, such as your health, disability, your interests, preferences and what you need assistance with from a PA or the qualities you are looking for in a PA User.

You do not have to provide any of this information and any information you do provide is only available to others who have registered as members of our Website. However, if you provide information which is optional in your profile you may find it easier and more effective in finding a suitable PA or PA User who matches your requirements. PA Pool is a closed environment accessible only if you are a registered member.

The detailed optional information is only collected for the purposes of the profiles on the website so that you can find other PA Pool members who match your requirements. We would not share this with third parties, without obtaining your consent or as required by law.

In some areas of our website, PA Pool requests that you provide personal data, including your name, postcode address, e-mail address and other information from which your identity is discernible. In other areas of our website, PA Pool collects or may collect demographic information that is not unique to you such as your postcode, age, gender and the types of work in which you are interested. Sometimes we collect or may collect a combination of the two types of information.

We also gather or may gather certain personal information about your use of our site, such as what areas you visit and what services you access. Moreover, there is information about your computer hardware and software that is or may be collected by PA Pool. This information may include your IP address, browser type, domain names, access times and referring web site addresses, but is not linked to your personal information.

We may sometimes afford you the opportunity to provide descriptive, cultural, behavioural, preferential and/or lifestyle information about yourself, but it is solely up to you whether you furnish such information. If you do provide such information, you are thereby consenting to the use of that information in accordance with the policies and practices described in this Privacy Policy. For example, such information may be used for the purpose of determining your potential interest in receiving e-mail or other communications about particular products or services.

Why we need it

We need to collect basic information (your name, postcode address, email address, date of birth) when you register so you can be set up as a member, allow you to receive new message notifications and to check that you satisfy the age requirement to use the Service.

You may also provide additional optional personal information. The optional information which you can provide relates to your membership profile and it is entirely up to you how much optional information you want to include.

If you want to use the paid features of our Service, personal information will also be collected so that you can pay the subscription fees. This will be collected and processed by Stripe on our behalf (see below on how your personal information is processed).

If you opted into receiving newsletters from us, we will also use your personal information to send you our newsletters. If you change your mind, you can unsubscribe at any time by clicking the unsubscribe button, changing your preferences in your 'My Settings' menu or by emailing us at admin@papool.co.uk.You don't have to disclose any of personal information to browse our Website but unless you register as a member you will not be able to access any of the PA or PA User profiles.

If you choose to withhold requested information, we may not be able to provide you with some of the Services (eg paid services, if you do not want to provide payment details) and you may find it less easy to find a PA or PA User who is a good fit for your needs if you do not include at least some of the optional information on your profile.

We will also process your personal information to ensure that members comply with our Membership Terms and Conditions, for example, to ensure that not more than one account is registered, no email addresses, telephone numbers or links to websites are included in profiles and to investigate any complaints and for statistical purposes.

Our marketing and other processing of personal information

Sometimes, with your consent, we will process your personal information to provide you with information about what we do and our services in the form of newsletters that you have requested or are expecting.

PA Pool also processes your information when it is in our legitimate interests to do this and where these interests do not override you rights for example to provide you with information about our services, feedback and to monitor overall use of the service on our Website and compile statistical data relating to this. Please see the section on ‘Legitimate Interest’ for more information.

On other occasions, we may process personal information when we need to do this to fulfil a contract (for example, to process the payment of) or where we are required to do this by law or other regulations.

How we obtain your details

We collect your personal information when you register to use our Website as a PA or PA User and at that time you will be able to opt in to receive email newsletters from time to time. If you subscribe for paid features of the service available through our Website, personal information will also be collected to process your payment of the subscription fees.

Children and those under 18

If you are under 18 please ensure you obtain your parent or guardian's consent before registering as a member and/or subscribing to the services, we offer via our Website and we would suggest that you go through our terms and conditions relating to use of the service before registering.

Please note that we will not knowingly accept persons aged under 18 years as members or subscribers to the paid features of the service we offer through our Website or market our services to them, unless their parent or guardian has given their consent market our Website or the service to them.

As a parent or guardian, we encourage you to be aware of the activities in which your children or young people are participating, both offline and online. If they voluntarily disclose information, this may encourage unsolicited messages. We suggest that you discourage your child from providing any information without your consent.

How your personal information is processed

Indigo Tree (https://indigotree.co.uk/) developed our Website, manages the database and undertake any website maintenance and updates. Indigo Tree are accredited by CyberEssentials a government backed security accreditation.

Our Website is hosted by Digital Ocean, which is based in the UK and our Blog uses WP Engine.

PA Pool does not hold or process payment data. We use Stripe which has been audited by an independent PCI Qualified Security Assessor (QSA) and is certified as a PCI Level 1 Service Provider. This is the most stringent level of certification available in the payments industry. The entity that provides Services in Europe is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin. In providing Stripe Services, Stripe Payments Europe transfers personal data to Stripe, Inc. in the US. To ensure the adequate protection of personal data, they have certified to the EU-U.S. and Swiss-U.S. Privacy Shield Framework.

Our newsletters are sent out via Campaign Monitor. Data is stored in the USA, which is protected by EU-U.S. Privacy Shield. Members are invited to opt in to receive newsletters when they register as a member but can change these preferences by using the unsubscribe button at the bottom of the newsletter.

PA Pool’s administration has no access to emails sent between members using the website email. Indigo Tree would be able to access this on our behalf if was necessary to deal with a complaint or security issues affecting members.

How you can update your personal information

You may review, correct, update or change your account profile information at any time. Simply log into your PA Pool account, go to 'Edit my Profile', review your account information and, if you wish, edit it with the options provided. You can also update your account details and notifications preferences at any time via your 'My Settings' menu. If you wish to delete your account, please contact us at admin@papool.co.uk. However, please note that if you do withdraw your consent, you may not be able to use the relevant services and your PA Pool account profile information will be deleted.

Posting to Public Areas of PA Pool

Please remember that if you post any of your personal information in member areas of PA Pool, such as online forums or chat rooms, or in the searchable database, such information may be collected and used by others over whom PA Pool has no control. We are not responsible for the use made by third parties of information you post or otherwise make available in member areas of PA Pool.

Security

PA Pool has implemented appropriate technical and organisational measures designed to secure your personal information from accidental loss and from unauthorised access, use, alteration or disclosure. In particular, all account and password data are encrypted (i.e. it is scrambled between your computer and PA Pools’ servers) and all traffic which is internal to the PA Pool network (such as access to our database) is also encrypted. Notwithstanding such measures, the Internet is an open system and we cannot guarantee that unauthorised third parties will never be able to defeat those measures or use your personal information for improper purposes.

Anything else?

Some of your personal information may be transferred and processed outside the European Economic Area (EEA) as some of our third party service providers are based outside the EEA as referred to in the ‘How your personal information is processed’ section above.

Countries outside of the do not always offer the same levels of protection to your personal information, so European law has prohibited transfers of personal data outside of the EEA unless the transfer meets certain criteria.

Whenever we transfer your personal data out of the EEA, we do our best to ensure a similar degree of security of data by ensuring at least one of the following safeguards is implemented:

We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission; or

Where we use certain service providers, we may use specific contracts or codes of conduct or certification mechanisms approved by the European Commission which give personal data the same protection it has in Europe; or

Where we use providers based in the United States, we may transfer data to them if they are part of the EU-US Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US.

If none of the above safeguards is available, we may request your explicit consent to the specific transfer. You will have the right to withdraw this consent at any time but if you do so you may not be able to use the Service.

Please email us at admin@papool.co.uk if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.

3. Legitimate interests

We have a number of lawful reasons that mean we can use your personal information. One of these is something called 'legitimate interests'.

This means that we have the potential to use your personal information if we have a genuine and legitimate reason and we are not harming any of your rights and interests.

So, what does this mean? When you provide your personal details to us we may use your information to prevent fraud, maintaining the security of our system, data analytics, enhancing, modifying or improving our services, identifying usage trends and determining the effectiveness of the service and newsletter campaigns.

Before doing this, though, we will also carefully consider and balance any potential impact on you and your rights.

How we may use your personal information

Ordering online: In order for us to process an order, payment has to be taken and contact information collected, such as name, and email address provided.

Your best interest: Processing your information to protect you against fraud when transacting on our website, and to ensure our websites and systems are secure and that members are complying with the membership terms and conditions.

Analytics: To use your personal information for the purposes of customer analysis, assessment, profiling and direct marketing, on a personalised or aggregated basis, to help us with our activities and to provide you with the most relevant information as long as this does not harm any of your rights and interests.

Research: To determine the effectiveness of the services and any newsletters we send you and to develop our services, systems and relationships with you.

Your interests

Before we use your personal information for our legitimate interests, we will always consider and balance any potential impact on you and your rights under data protection legislation and any other relevant law. Our legitimate business interests do not automatically override your interests – we will never use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).

4. Sharing your information

We do not share your information with any other organisations or individuals unless we are when obliged to by law, for purposes of national security, taxation and criminal investigations and in the following instances:

If you have agreed that we may do so

When we use other companies to provide services on our behalf, e.g. those hosting and maintaining our website or blog, storing back-up copies, processing and sending mail and emails, members analysis, assessment, providing marketing assistance and customer services, when using auditors/advisors or processing credit/debit card payments. These companies and individuals will have access to your personal information as necessary to perform their functions, but they may not share that information with any other third party or use that data for any other purpose. We will retain control of and be responsible for any information shared in this way.

We may disclose such information if legally required to do so, if requested to do so by a governmental entity or regulatory authority or if we believe in good faith that such action is necessary to: (a) conform to legal requirements or comply with legal process; (b) protect the rights or property of PA Pool; (c) prevent a crime or protect national security; or (d) protect the personal safety of users or the public.

If we merge with another organisation to form a new entity, information may be transferred to the new entity. In addition, in the event PA Pool becomes the subject of an insolvency proceeding, whether voluntary or involuntary, PA Pool or its liquidator, administrator, receiver or administrative receiver may sell, license or otherwise dispose of such information in a transaction approved by the court. You will be notified of sale of all or a substantial portion of our business to a third party by email or through a prominent notice posted on the PA Pool site.

We may disclose aggregate statistics about our site visitors, members and subscribers to describe our services and operations to prospective partners, advertisers and other reputable third parties and for other lawful purposes, but these statistics won’t include any personally identifying information.

And, we will never sell or rent your personal information to other organisations.

5. Retaining your information

We hold your information only as long as necessary for each reason that we use it. We have provided some examples of the time we will keep your information in this paragraph, but you can contact us for more information.

If you decide not to use the service having registered to do so or cease to do so, we will retain your personal information for a period of 24 months after you cease to use the Service, unless we are required to keep any such personal data by applicable law, for compliance purposes or need to retain it to deal with any matters arising in relation to compliance with the membership terms and conditions.

If you unsubscribe from the service and/or our newsletters, we will keep some basic information in order to avoid sending you unwanted materials in the future and to ensure that we don’t accidentally send you information that you did not wish to receive.

If you subscribe for the paid features of the service, we will keep the purchase information for a period of seven years for accounting purposes. We may also keep information about your membership to comply with legal requirements including ensuring that you have complied with the terms of membership that apply to the services offered through our Website and to deal with any complaints we receive about members.

6. Our Cookie Policy and use of Web Beacons

PA Pool uses "cookies" to help personalise and maximise your online experience and time online. A cookie is a text file that is either stored in your computer’s memory temporarily (a “session” cookie) or placed on your hard drive (a “persistent” cookie) by a web page server. Cookies are not used to run programmes or deliver viruses to your computer. Cookies are uniquely assigned to you and your computer and can only be read by a web server in the domain that issued the cookie to you.

One of the primary purposes of cookies is to provide a convenience feature to save you time. The purpose of a cookie is to tell the web server that you have returned to a specific page. When you return to the PA Pool site, cookies enable us to retrieve the information you previously provided, so you can easily use the features that you customised. For example, if you personalise PA Pool pages, or register for services, a cookie helps us to recall your specific information (such as user name, password and preferences).

In addition, third party advertisers on the web site may use “cookies”. PA Pool has no control over, and is not responsible for, the practices of those third party advertisers. PA Pool encourages you to review the policies of such advertisers.

Although you may configure your browser not to accept cookies, you will find the website functionality impaired if you do so.

PA Pool web pages may contain electronic images known as web beacons (sometimes called single-pixel gifs) that allow us to count users who have visited those pages and to deliver co-branded services. Web beacons are not used to access your personally identifiable information on PA Pool; they are a technique we use to compile aggregated statistics about our web site usage.

Web beacons collect only a limited set of information including a cookie number, time and date of a page view, and a description of the page on which the web beacon resides.

Because web beacons are the same as any other content request included in the recipe page, you cannot opt out or refuse them. However, they can be rendered ineffective by either opting out of cookies or changing the cookie setup in your browser.

Third parties are not permitted to use web beacons on the PA Pool sites.

7. What are your rights?

You have a number of rights about how the personal information you provide can be used.

These are:

Transparency over how we use your personal information (right to be informed).

The ability to request a copy of the information we hold about you, which will be provided to you within one month (right of access).

Update or amend the information we hold about you if it is wrong (right of rectification).

Ask us to stop using your information (right to restrict processing).

Ask us to remove your personal information from our records (right to be 'forgotten').

Object to the processing of your information for marketing purposes (right to object).

Not be subject to a decision when it is based on automated processing (automated decision making and profiling).

If you would like to know more about your rights under the data protection law, you can find out more at the Information Commissioners Office website.

Remember, you can change the way you hear from us or withdraw your permission for us to process your personal information at any time by using the unsubscribe button, changing your preferences in your 'My Settings' menu, or by contacting us at admin@papool.co.uk.

8. How to contact us

If you wish to talk through anything in our privacy policy, find out more about your rights or obtain a copy of the information we hold about you, please contact us (details at the bottom of this page), we will be happy to help.

If you wish to raise a complaint on how we have handled your personal information, you can contact our administrator who will investigate the matter. If you are not satisfied with our response or believe we are not processing your personal information in accordance with the law, you can complain to the Information Commissioner’s Office (ICO).

Our administrator can be contacted by emailing: admin@papool.co.uk.

Links to other websites

Our site contains links to other websites over which we have no control. PA Pool is not responsible for the privacy policies or practices of other web sites to which you choose to link from this site. We encourage you to review the privacy policies of those other web sites, so you can understand how they collect, use and share your information.